linux-fsdevel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Jamie Lokier <jamie@shareable.org>
To: "Bodo Eggert <harvested.in.lkml@posting.7eggert.dyndns.org>"
	<7eggert@gmx.de>
Cc: Miklos Szeredi <miklos@szeredi.hu>,
	dan@debian.org, linux-fsdevel@vger.kernel.org,
	linux-kernel@vger.kernel.org, hch@infradead.org, akpm@osdl.org,
	viro@parcelfarce.linux.theplanet.co.uk
Subject: Re: [RFC] FUSE permission modell (Was: fuse review bits)
Date: Tue, 12 Apr 2005 15:37:07 +0100	[thread overview]
Message-ID: <20050412143707.GD10995@mail.shareable.org> (raw)
In-Reply-To: <E1DLKOd-0001Nd-MG@be1.7eggert.dyndns.org>

Bodo Eggert <harvested.in.lkml@posting.7eggert.dyndns.org> wrote:
> >> That is exactly the intended effect.  If I'm at my work machine (where
> >> I'm not an admin unfortunately) and I mount my home machine with sshfs
> >> (because FUSE is installed fortunately :), then I bloody well don't
> >> want the sysadmin or some automated script of his to go mucking under
> >> the mountpoint.
> > 
> > I think that would be _much_ nicer implemented as a mount which is
> > invisible to other users, rather than one which causes the admin's
> > scripts to spew error messages.  Is the namespace mechanism at all
> > suitable for that?
> 
> This will require shared subtrees plus a way for new logins from the same
> user to join an existing (previous login) namespace.

Or "per-user namespaces".

It's part of a more general problem of how you limit access to private
data such as crypto keys, either per user, or more finely than that.

Isn't that what all the keyring stuff is for?

-- Jamie

  parent reply	other threads:[~2005-04-12 14:37 UTC|newest]

Thread overview: 70+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <3S8oM-So-11@gated-at.bofh.it>
     [not found] ` <3S8oM-So-13@gated-at.bofh.it>
     [not found]   ` <3S8oN-So-15@gated-at.bofh.it>
     [not found]     ` <3S8oN-So-17@gated-at.bofh.it>
     [not found]       ` <3S8oN-So-19@gated-at.bofh.it>
     [not found]         ` <3S8oN-So-21@gated-at.bofh.it>
     [not found]           ` <3S8oN-So-23@gated-at.bofh.it>
     [not found]             ` <3S8oN-So-25@gated-at.bofh.it>
     [not found]               ` <3S8oN-So-27@gated-at.bofh.it>
     [not found]                 ` <3S8oM-So-7@gated-at.bofh.it>
     [not found]                   ` <3SbPN-3T4-19@gated-at.bofh.it>
2005-04-12  9:17                     ` [RFC] FUSE permission modell (Was: fuse review bits) Bodo Eggert <harvested.in.lkml@posting.7eggert.dyndns.org>
2005-04-12 14:45                       ` Jamie Lokier
2005-04-12 15:19                         ` Miklos Szeredi
2005-04-12 16:04                           ` Jamie Lokier
2005-04-12 16:31                             ` Miklos Szeredi
2005-04-12 16:44                               ` Jamie Lokier
2005-04-12 16:55                                 ` Miklos Szeredi
2005-04-12 17:13                                   ` Jamie Lokier
2005-04-12 19:08                                     ` Miklos Szeredi
2005-04-13 12:56                                       ` Jan Hudec
2005-04-13 15:08                                         ` Miklos Szeredi
2005-04-13 16:13                                           ` Jamie Lokier
2005-04-13 16:47                                             ` Miklos Szeredi
2005-04-13 16:57                                               ` Jamie Lokier
2005-04-13 15:58                                         ` Jamie Lokier
2005-04-12 20:19                         ` Anton Altaparmakov
2005-04-12 21:52                           ` Jamie Lokier
2005-04-13  9:14                             ` Miklos Szeredi
2005-04-13 12:59                               ` Jan Hudec
2005-04-13 17:02                               ` Jamie Lokier
2005-04-13 17:29                                 ` Miklos Szeredi
2005-04-13 18:36                                   ` Jamie Lokier
2005-04-13 19:16                                     ` Miklos Szeredi
     [not found]                   ` <3S9b7-1yl-1@gated-at.bofh.it>
     [not found]                     ` <3S9uB-1Lj-3@gated-at.bofh.it>
     [not found]                       ` <3SbG5-3Mb-41@gated-at.bofh.it>
     [not found]                         ` <3ScC1-4zl-1@gated-at.bofh.it>
     [not found]                           ` <3ScLO-4GA-9@gated-at.bofh.it>
     [not found]                             ` <3SdeV-54h-21@gated-at.bofh.it>
     [not found]                               ` <3SeXf-6BK-21@gated-at.bofh.it>
     [not found]                                 ` <E1DLKOd-0001Nd-MG@be1.7eggert.dyndns.org>
2005-04-12 14:37                                   ` Jamie Lokier [this message]
2005-04-12 19:51                                     ` Bodo Eggert
     [not found]                   ` <3UmnD-6Fy-7@gated-at.bofh.it>
2005-04-17 23:52                     ` Bodo Eggert <harvested.in.lkml@posting.7eggert.dyndns.org>
2005-04-19 11:57                       ` Eric Van Hensbergen
2005-04-19 15:01                         ` Bodo Eggert
2005-04-19 15:21                           ` Miklos Szeredi
2005-04-19 15:26                           ` Eric Van Hensbergen
2005-04-19 16:02                             ` Bodo Eggert
2005-04-19 19:29                               ` Eric Van Hensbergen
2005-04-20  3:59                                 ` Mike Waychison
2005-04-20  7:09                                   ` Miklos Szeredi
     [not found] <3UrQt-2Js-3@gated-at.bofh.it>
     [not found] ` <3SpIW-6UA-17@gated-at.bofh.it>
     [not found]   ` <3SpIW-6UA-19@gated-at.bofh.it>
     [not found]     ` <3SpIW-6UA-21@gated-at.bofh.it>
     [not found]       ` <3UrQt-2Js-5@gated-at.bofh.it>
     [not found]         ` <3UrQt-2Js-1@gated-at.bofh.it>
     [not found]           ` <3UZyS-55i-39@gated-at.bofh.it>
     [not found]             ` <3V2wG-7HR-19@gated-at.bofh.it>
     [not found]               ` <3V2PX-7Vh-23@gated-at.bofh.it>
     [not found]                 ` <3V6Ae-2Ce-17@gated-at.bofh.it>
     [not found]                   ` <3V6JW-2K9-49@gated-at.bofh.it>
     [not found]                     ` <3VeHl-NF-3@gated-at.bofh.it>
2005-04-20 19:52                       ` Bodo Eggert <harvested.in.lkml@posting.7eggert.dyndns.org>
     [not found] <20050320151212.4f9c8f32.akpm@osdl.org>
     [not found] ` <20050321073519.GA13879@outpost.ds9a.nl>
     [not found]   ` <20050323083347.GA1807@infradead.org>
     [not found]     ` <E1DE2D1-0005Ie-00@dorka.pomaz.szeredi.hu>
     [not found]       ` <20050325095838.GA9471@infradead.org>
     [not found]         ` <E1DEmYC-0008Qg-00@dorka.pomaz.szeredi.hu>
     [not found]           ` <20050331112427.GA15034@infradead.org>
     [not found]             ` <E1DH13O-000400-00@dorka.pomaz.szeredi.hu>
     [not found]               ` <20050331200502.GA24589@infradead.org>
     [not found]                 ` <E1DJsH6-0004nv-00@dorka.pomaz.szeredi.hu>
     [not found]                   ` <20050411114728.GA13128@infradead.org>
2005-04-11 14:43                     ` Miklos Szeredi
2005-04-11 15:36                       ` Daniel Jacobowitz
2005-04-11 15:56                         ` Miklos Szeredi
2005-04-11 18:17                           ` Daniel Jacobowitz
2005-04-11 19:10                             ` Miklos Szeredi
2005-04-11 19:22                               ` Daniel Jacobowitz
2005-04-11 19:56                                 ` Miklos Szeredi
2005-04-11 21:41                                   ` Jamie Lokier
2005-04-12  6:10                                     ` Miklos Szeredi
2005-04-12 14:33                                       ` Jamie Lokier
2005-04-12 15:13                                         ` Miklos Szeredi
2005-04-12 16:03                                           ` Miklos Szeredi
2005-04-12 15:16                                         ` Frank Sorenson
2005-04-12 15:56                                           ` Jamie Lokier
2005-04-17 17:45                                       ` Eric Van Hensbergen
2005-04-17 18:06                                         ` Jamie Lokier
2005-04-12 20:36                                     ` Anton Altaparmakov
2005-04-11 22:13                                   ` Daniel Jacobowitz
2005-04-12  6:27                                     ` Miklos Szeredi
2005-04-12 14:32                                       ` Jamie Lokier
2005-04-12 14:59                                         ` Miklos Szeredi
2005-04-12 16:13                                           ` Jamie Lokier
2005-04-12 16:37                                             ` Miklos Szeredi
2005-04-12 16:45                                               ` Jamie Lokier
2005-04-12 16:52                                                 ` Miklos Szeredi
2005-04-12 17:14                                                   ` Jamie Lokier
2005-04-12 19:10                                                     ` Miklos Szeredi
2005-04-12 16:42                                             ` Jan Hudec
2005-04-12  8:06                           ` Jan Hudec
2005-04-11 18:22                       ` Jamie Lokier
2005-04-11 18:27                         ` Daniel Jacobowitz
2005-04-11 19:38                         ` Miklos Szeredi
2005-04-17 18:01                       ` Eric Van Hensbergen
2005-04-17 18:45                         ` Miklos Szeredi
2005-04-17 19:57                           ` Eric Van Hensbergen

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20050412143707.GD10995@mail.shareable.org \
    --to=jamie@shareable.org \
    --cc=7eggert@gmx.de \
    --cc=akpm@osdl.org \
    --cc=dan@debian.org \
    --cc=hch@infradead.org \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=miklos@szeredi.hu \
    --cc=viro@parcelfarce.linux.theplanet.co.uk \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).